Roundupwp

Registrations For The Events Calendar

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 25.03.2025 06:00:09
  • Zuletzt bearbeitet 15.05.2025 19:07:43

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_...

Exploit
  • EPSS 1.37%
  • Veröffentlicht 08.11.2024 06:15:17
  • Zuletzt bearbeitet 15.05.2025 16:42:46

The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

  • EPSS 0.11%
  • Veröffentlicht 01.11.2024 15:15:39
  • Zuletzt bearbeitet 01.11.2024 20:24:53

Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1.

  • EPSS 0.59%
  • Veröffentlicht 29.08.2024 15:15:27
  • Zuletzt bearbeitet 13.09.2024 21:00:44

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.1...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 24.01.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 05:54:19

The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

Exploit
  • EPSS 55.45%
  • Veröffentlicht 06.12.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:54:03

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statem...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 29.11.2021 09:15:07
  • Zuletzt bearbeitet 21.11.2024 05:53:56

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting